📊 Key Data
  • 2026 Partnership: Faction Networks and iVALT collaborate to integrate AI-resistant identity verification into Zero Trust architecture.
  • 5-Factor Verification: iVALT's platform combines biometrics, device health, location, behavioral patterns, and more for continuous identity assessment.
  • Q3 2026 Launch: The integrated solution is expected to be commercially available in the third quarter of 2026.
🎯 Expert Consensus

Experts would likely conclude that this partnership represents a significant advancement in cybersecurity by addressing the critical gap of human identity verification within Zero Trust frameworks, particularly in an era of sophisticated AI-driven threats.

29 days ago

Zero Trust's Next Leap: Verifying the Human Behind Every Digital Action

ROME, N.Y. and SAN JOSE, Calif. – June 22, 2026 – For years, the guiding principle of modern cybersecurity has been "Zero Trust," a framework built on the stark reality that no user or device can be trusted by default. But as security models have successfully locked down networks and devices, attackers have simply shifted their focus to the weakest link: human identity. Now, a strategic partnership between Faction Networks and iVALT aims to close this final, critical gap, pushing the frontier of security from verifying a connection to verifying the human—or human-sponsored AI—behind it.

Announced today, the collaboration integrates iVALT’s AI-resistant identity verification platform directly into Faction’s “Generation 3” Zero Trust architecture. The goal is ambitious yet essential in an era of sophisticated phishing, session hijacking, and AI-generated deepfakes: to create a digital environment where every significant action is cryptographically signed and traceable to a confirmed human being who is present and accountable.

The Evolving Battlefield of Digital Trust

The concept of Zero Trust has matured significantly since its inception. Early implementations focused on network micro-segmentation, creating small, isolated zones to limit an attacker's lateral movement. The next evolution acknowledged that with cloud adoption and remote work, identity had become the new perimeter. Yet, even with multi-factor authentication (MFA), identity remains the most exploited vector. Credentials can be phished, session tokens can be stolen, and increasingly, AI can be used to convincingly mimic a legitimate user.

This is the problem Faction Networks and iVALT assert they can solve. Faction has built its name on what it calls "Generation 3 Zero Trust," which emphasizes customer-owned and controlled networks. Their architecture keeps encryption keys and the control plane off the public internet, rendering the network infrastructure invisible to external attackers. "Historically, cybersecurity has focused on securing devices and connections while assuming the person behind them can be trusted," said Leroy Williams, President & CEO of Faction Networks. "iVALT closes that gap by enabling customers to verify that an authenticated human is directing activity on the network."

The partnership’s core innovation is embedding iVALT’s authentication engine inside this private, owner-controlled network. Unlike standard security stacks that rely on cloud authentication brokers, this design ensures that sensitive biometric and authentication traffic never traverses the public internet. This materially strengthens an organization's security posture, making it immune to external interception or spoofing and independent of a third-party cloud provider's uptime.

Forging an AI-Resistant Identity

At the heart of the joint solution is iVALT's Digital Trust platform, which moves far beyond traditional passwords and simple MFA. It employs a combination of passwordless biometrics and what it terms "5-Factor verification." While the precise factors are proprietary, this approach typically combines biometrics ("something you are") with contextual data like device health, user location, and even behavioral patterns ("something you do") to build a high-fidelity, continuous assessment of identity.

The system is designed to be "AI-resistant," a crucial claim in an age of generative AI. This means it incorporates advanced liveness detection and anti-spoofing technologies to differentiate between a real human and a digitally fabricated deepfake or synthetic voice command. By continuously validating a user's presence, the platform also aims to close the door on session-hijacking attacks, where an attacker takes over an already authenticated session.

"Traditional security focuses on the connection. Together, Faction and iVALT secure the trust behind it," stated Baldev Krishan, Ph.D., President & CEO of iVALT. This shift from authenticating a login to verifying the intent behind every critical action is what the companies are calling "Human-in-the-Loop" security. For high-risk operations—like authorizing a major financial transaction or deploying critical code—the system can trigger a step-up verification, ensuring a present, accountable human has approved the action.

Establishing Accountability in the Age of AI

Perhaps the most forward-looking aspect of the partnership is its direct confrontation with the challenge of AI governance. As organizations delegate more operational responsibility to autonomous AI agents, the question of accountability becomes paramount. If an AI agent makes a mistake or is compromised, who is responsible? The Faction-iVALT solution addresses this through a feature dubbed "AI Security & Control."

iVALT’s Intelligent Public Key Infrastructure (PKI) extends identity to machines and AI agents, binding them cryptographically to a human sponsor. Every AI agent operating within the Faction network carries a verifiable digital identity derived from the human who authorized it. Its actions are then bounded by policies set by that sponsor and are fully auditable. Governance is no longer a feature bolted on at the application layer but is enforced at a fundamental network and identity level.

This capability is not merely a technical curiosity; it directly addresses growing regulatory and business risks. With frameworks like the EU AI Act imposing strict requirements for human oversight and traceability in high-risk AI systems, having a built-in, cryptographically signed audit trail of AI actions tied to a human sponsor could become a critical component of compliance.

"As AI agents take on more of the work, the question is no longer just whether a connection is allowed, but who or what is acting, what authority they hold, and which human is accountable," Krishan noted. The integrated platform promises to answer that question at the point of action, creating a clear line of responsibility from human sponsor to agent execution.

The initial integration between the two companies is complete, with joint development underway. For organizations grappling with the dual challenges of sophisticated identity attacks and the rapid adoption of AI, the promise of a unified architecture that verifies the human behind every action is a significant signal in the noise of a complex digital world. The integrated solution is expected to be commercially available in the third quarter of 2026.

Topics & Related

Sector:
Cybersecurity
Theme:
Agentic AI
Zero Trust
Identity & Access Management
Event:
Partnership
UAID: 37780